CyberNews: 12/08/2026 Edition

Published by Dunateo on 2026-08-12

Today’s roundup

  • Microsoft Patch Tuesday for August 2026 Fixed a Zero-Day and Wormable RCE
  • Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack
  • ShieldBreak: New Windows Zero-Day Bypasses Microsoft’s RoguePlanet Patch
  • Zoom Patches “Zoomsday” Zero-Click Flaw Enabling Remote Code Execution
  • Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
  • SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
  • Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
  • Ransomware group hijacks hospital system’s Facebook page amid ongoing cyberattack fallout
  • Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
  • Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
  • Summary

    Microsoft's August 2026 Patch Tuesday addressed 398 vulnerabilities, including an actively exploited zero-day (CVE-2026-68820) in the Windows WinSock driver (afd.sys) and a critical wormable DNS flaw (CVE-2026-62878) allowing remote code execution without authentication. The updates also fixed an Exchange server authentication bypass demonstrated at Pwn2Own.

    Check Point Research detailed "Operation Dream Job," a campaign by the Lazarus group targeting the defense sector via fake job offers. The attackers distributed trojanized PDF viewers to deploy the FudModule rootkit, exploiting the same Windows AFD.sys zero-day (CVE-2026-68820) to gain SYSTEM privileges, bypass EDR, and install the new Troy backdoor and RelayShell webshell from compromised web servers.

    A security researcher, Chaotic Eclipse (Nightmare Eclipse), released a proof-of-concept for "ShieldBreak," a new Microsoft Defender zero-day. This exploit effectively bypasses the patch for CVE-2026-50656 (RoguePlanet), a race condition vulnerability, allowing SYSTEM-level privilege escalation on fully updated Windows 11 and Server 2025 systems.

    Zoom patched critical zero-click remote code execution (RCE) flaws, including CVE-2026-53413, dubbed "Zoomsday." This vulnerability in Zoom's annotation feature allowed an attacker to take full control of any meeting participant's device across all platforms without user interaction. Other patched flaws included buffer overread and use-after-free issues.

    Threat actors are actively exploiting CVE-2026-59310 (CVSS 9.8), a critical directory-traversal vulnerability in Broadcom VMware vCenter server. Malicious actors with network access can leverage this flaw to execute arbitrary code and gain persistent remote access to affected systems.

    SAP released patches for a maximum-severity (CVSS 10.0) security flaw, CVE-2026-58231, in its Commerce Cloud Data Hub Adapter. The vulnerability, caused by insufficient authorization checks and input validation, could allow unauthenticated attackers to execute arbitrary code on the platform.

    Adobe addressed three critical security vulnerabilities, including CVE-2026-48362 (CVSS 10.0), impacting ColdFusion, Commerce, and Campaign Classic. These flaws, if successfully exploited, could lead to arbitrary code execution and privilege escalation on affected systems.

    A ransomware group successfully hijacked the Facebook page of a hospital system, threatening to leak 6 terabytes of highly sensitive patient data. The stolen information reportedly includes records related to sexual assault, mental health, abortions, and sexual harassment incidents, highlighting the severe impact of cyberattacks on healthcare.

    Two malicious LiteLLM releases were found on PyPI in March, containing credential-stealing code. These releases harvested cloud keys, SSH keys, Kubernetes tokens, and database passwords, potentially exposing over 2,100 organizations, as reported by threat intelligence firm CloudSEK based on captured data.

    The Russian threat group Sandworm (UAC-0145) is targeting IT professionals with fake job offers to distribute a trojanized WireGuard VPN client. This social engineering campaign, observed since May, aims to trick system administrators into installing malware that can execute commands on their systems.

    Want to dig deeper?

    Vulnerabilities

    CVE-2026-68820 High
    CVE-2026-62878 Critical
    CVE-2026-50656 High
    CVE-2026-53413 Critical
    CVE-2026-59310 Critical
    CVE-2026-58231 Critical
    CVE-2026-48362 Critical

    Cyber Groups

    Lazarus Group Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC, NICKEL ACADEMY, Diamond Sleet